Videos IvE8n-ylFYY
Privacy-Preserving Intelligence — Steve Korshakov, Bee (acq. Amazon)
Scene timeline
41 shot(s).
keyframes kept every frame deduplicated
What was stored
- cues
- 152
- whisperx 152
- chunks
- 27
- from 152 cues
- keyframes
- 25
- kept of 41 captured
- frames with text
- 25
- 457 lines read
- chapters
- 9
- from the source metadata
- keyframe bytes
- 5.7 MB
- word timings on 152 cues
Provenance
| stage | state | model | started | took |
|---|---|---|---|---|
fetch |
done | — | 2026-08-10 00:16 | 2m 15s |
stt |
done | — | 2026-08-10 00:18 | 14s |
chunk |
done | — | 2026-08-10 00:18 | 0s |
text_embed |
done | — | 2026-08-10 19:43 | 1s |
keyframe |
done | — | 2026-08-10 00:18 | 1m 39s |
ocr |
done | — | 2026-08-10 00:20 | 9s |
frame_embed |
done | — | 2026-08-10 19:43 | 4s |
Frames, and what the machine read
-
- AlEngineer0.96
- World's Fair1.00
-
- AIEngineer0.95
- World's Fair0.99
-
- LAB & PLATINUM SPONSORS0.99
- Amazon AGI Lab0.98
- ANTHROP\C1.00
- Google DeepMind1.00
- MINIMAX0.97
- OpenAI0.92
- Akamai1.00
- arize0.92
- aws1.00
- Braintrust bright data0.98
- B1.00
- Browserbase1.00
- docker1.00
- :neo4j0.93
- ORACLE1.00
- PayPal1.00
- qodo1.00
- reducto1.00
- Sonar1.00
- Makers of0.99
- togetherai1.00
- Unblocked1.00
- WorkOS1.00
- SonarQube1.00
-
- 二0.68
- AlEngineer1.00
- World's Fair0.99
-
- AlEngineer0.98
- World's Fair0.97
- Amazon Bee1.00
- PRESENTED BY1.00
- Privacy Preserving1.00
- Microsoft1.00
- Intelligence1.00
- Steve Korshakov 20261.00
- World's Fair0.96
- Engineering the future of Al1.00
-
- AlEngineer0.98
- World's Fair0.97
- PRESENTED BY1.00
- Microsoft1.00
- What is Bee?_0.99
- $50 always-on wearable1.00
- with a microphone1.00
- Proactive AI agent1.00
- acts on your behalf1.00
- +0.82
- API + CLI access0.99
- freely access your data1.00
- World'sFair1.00
- Engineering the future of Al0.99
-
- AlEngineer0.98
- A Year of Human Signals.0.99
- World's Fair0.98
- The data around one person is large, sensitive, and still incomplete.1.00
- PRESENTED BY1.00
- Microsoft1.00
- 10M spoken / heard0.99
- 20M+ in email1.00
- Highly sensitive1.00
- Life is mostly offline0.98
- Roughly ten million0.99
- Written communication1.00
- Even one week of1.00
- Much of human life still1.00
- tokens per year from1.00
- alone can exceed twenty0.98
- continuous recording can1.00
- happens outside the digital1.00
- conversations,listening,1.00
- million tokens in a year.0.99
- reveal health, family,1.00
- world, beyond apps and0.99
- and ambient speech.1.00
- fears, and desires.1.00
- documents.1.00
- < Rich signal. High sensitivity. Incomplete digital coverage. >0.99
- World's Fair0.98
- Engineering the future of Al0.99
-
- AlEngineer0.99
- A Year of Human Signals.0.99
- World's Fair0.97
- The data around one person is large, sensitive, and still incomplete.0.99
- 10M spoken / heard0.99
- 20M+ in email1.00
- Highly sensitive1.00
- Life is mostly offline0.98
- Roughly ten million0.98
- Written communication1.00
- Even one week of1.00
- Much of human life still1.00
- tokens per year from1.00
- alone can exceed twenty1.00
- continuous recording can1.00
- happens outside the digital0.99
- conversations,listening,1.00
- million tokens in a year.1.00
- reveal health, family,1.00
- world, beyond apps and1.00
- and ambient speech.1.00
- fears, and desires.1.00
- documents.1.00
- < Rich signal. High sensitivity. Incomplete digital coverage. >0.99
- World's Fair0.98
- TRACK 5·JUNE 30,20260.98
- Security1.00
-
- AlEngineer0.98
- Five Principles Behind Bee0.99
- World's Fair0.98
- The system design choices behind a stateful personal AI.1.00
- [0]→[]→[]0.86
- 24/70.97
- 1. Always on1.00
- 2. Acts proactively1.00
- 3. Developer velocity1.00
- 4. Boring infrastructure0.99
- 5. Power aware0.98
- Runs persistently, not0.99
- Can observe, decide, and0.98
- Easy to build, test, and0.98
- Use reliable, well-1.00
- Respect battery,1.00
- only during a single1.00
- take action on the user's0.98
- iterate quickly.1.00
- understood systems over1.00
- bandwidth, and local1.00
- request.1.00
- behalf.1.00
- clever complexity.1.00
- resources.0.99
- Stateful. Connected. Practical.1.00
- World's Fair0.99
- TRACK 5· JUNE 30,20260.95
- Security1.00
-
- Request-response vs Stateful Personal AI0.99
- AlEngineer0.99
- World'sFair1.00
- Most AI products are optimized for single inference calls. We are building a persistent system that1.00
- keeps state, connects to services, and can act over time.0.99
- Request-response systems1.00
- Bee1.00
- - Often stateless at the model layer0.99
- - Stateful runtime with persistent memory0.99
- - Context can be managed by the client0.99
- - Shared context across sessions and devices0.99
- Good for chat and short tasks0.98
- - Connected to tools and services0.99
- - Usually requires the app/device to initiate work0.99
- Can run background agents and take actions1.00
- - Limited background actions when the user is0.99
- on behalf of the user0.99
- away or offline0.99
- - Does not require the user's device to stay active0.99
- Mail /0.95
- Files /0.98
- API /0.94
- Calendar1.00
- Drive1.00
- MCP1.00
- request1.00
- External1.00
- Bee AI0.98
- Agents1.00
- LLM API1.00
- stateful1.00
- 3rd Party1.00
- user / device0.98
- response1.00
- user1.00
- Services1.00
- client-managed context1.00
- Apps1.00
- Request-response is a useful interface. We believe stateful systems are the next step for personal AI.1.00
- World'sFair1.00
- TRACK 5· JUNE 30, 20260.97
- Security1.00
-
- Security by Design_1.00
- AlEngineer0.99
- World's Fair0.97
- Customer data should remain private, encrypted, auditable, and protected by a minimal trust base.0.99
- Customer-only1.00
- Encrypted1.00
- Transparent +0.97
- Minimal trust0.99
- access1.00
- by default1.00
- auditable0.96
- base1.00
- Only the customer0.99
- Encrypt data in1.00
- Builds, deployments,1.00
- Trust Nitro hardware,1.00
- should be able to0.97
- transit and at rest,1.00
- and access paths1.00
- public Sigstore, and1.00
- and through every0.99
- read the data.1.00
- handling path.1.00
- should be visible,1.00
- narrow cross-org1.00
- E2TEE for inference1.00
- verifiable, and1.00
- controls.1.00
- (end-to-end, enclave-1.00
- traceable.1.00
- to-enclave encryption).1.00
- World's Fair0.99
- TRACK 5·JUNE 30,20260.97
- Security1.00
-
- Key Management & Attested Access_0.95
- AlEngineer0.99
- World's Fair0.99
- The account key is created on the user's device, shared only with attested runtimes,0.99
- replicated only across attested backend nodes, and expires automatically.1.00
- 1. Account key on device1.00
- 2. Device attests backend0.99
- 3. Key released to1.00
- attested runtime1.00
- Replicated across1.00
- attested nodes0.98
- 5. Expiry0.99
- 7d1.00
- Account key is generated1.00
- Stored in Secure Enclave /0.98
- on the device0.99
- Android Keystore1.00
- Secure backup via0.97
- Apple Keychain /1.00
- Google Play Block Store0.97
- Before sharing the key,1.00
- the client verifies the1.00
- Checks happen during1.00
- Verifies transparency1.00
- backend runtime1.00
- TLS connection1.00
- Verifies attestation1.00
- evidence1.00
- log inclusion in Sigstore0.99
- √ Only after attestation0.98
- √ No operator or employee0.99
- √ Key is available only0.98
- succeeds, the client1.00
- sends the account key0.98
- has direct access0.98
- inside the attested1.00
- runtime0.97
- Replicated in memory0.98
- Background nodes attest0.99
- Supports background work0.98
- each other before key1.00
- sharing1.00
- across trusted background1.00
- nodes1.00
- for up to 7 days0.96
- Cached keys expire1.00
- after 7 days1.00
- Without a fresh key0.99
- from the device, data1.00
- cannot be decrypted1.00
- device-created key0.98
- device attests backend1.00
- key shared after attestation1.00
- mutually attested node replication1.00
- 7 day expiry1.00
- Device-owned key1.00
- Sigstore-verified attestation0.99
- Mutual node attestation1.00
- No standing human access0.99
- The account key is created1.00
- Runtimes are verified via1.00
- Background nodes mutually0.99
- No operator or employee can1.00
- and controlled by the user's1.00
- attestation evidence and1.00
- attest each other before0.99
- access keys or plaintext1.00
- device.1.00
- Sigstore transparency logs.1.00
- replication.1.00
- data.1.00
- World's Fair0.97
- TRACK 5·JUNE 30,20260.98
- Security1.00
-
- Key Management &Attested Access_0.97
- AlEngineer0.98
- World's Fair0.96
- The account key is created on the user's device, shared only with attested runtimes,0.99
- replicated only across attested backend nodes, and expires automatically.1.00
- 1. Account key on device1.00
- 2. Device attests backend1.00
- 3. Key released to1.00
- attested runtime1.00
- Replicated across1.00
- attested nodes1.00
- 5. Expiry0.99
- PRESENTED BY0.98
- 7d1.00
- Microsoft1.00
- Account key is generated1.00
- Stored in Secure Enclave /0.99
- on the device0.97
- Android Keystore1.00
- Secure backup via0.99
- Apple Keychain /1.00
- Google Play Block Store0.97
- Before sharing the key,1.00
- the client verifies the0.95
- Checks happen during1.00
- Verifies transparency1.00
- backend runtime0.97
- TLS connection1.00
- Verifies attestation1.00
- evidence1.00
- log inclusion in Sigstore1.00
- √ Only after attestation0.97
- √ No operator or employee0.99
- √ Key is available only0.98
- succeeds, the client1.00
- sends the account key0.97
- has direct access0.98
- runtime0.96
- inside the attested1.00
- Replicated in memory0.99
- Background nodes attest0.99
- Supports background work0.99
- each other before key0.99
- sharing1.00
- across trusted background1.00
- nodes1.00
- for up to 7 days0.97
- Cached keys expire1.00
- after 7 days0.95
- Without a fresh key0.99
- from the device, data0.98
- cannot be decrypted1.00
- device-created key0.99
- device attests backend1.00
- key shared after attestation1.00
- mutually attested node replication1.00
- 7 day expiry1.00
- Device-owned key1.00
- Sigstore-verified attestation0.99
- Mutual node attestation1.00
- No standing human access0.99
- The account key is created0.99
- Runtimes are verified via0.99
- Background nodes mutually0.97
- No operator or employee can0.98
- and controlled by the user's1.00
- attestation evidence and1.00
- attest each other before0.98
- access keys or plaintext1.00
- device.1.00
- Sigstore transparency logs.1.00
- replication.1.00
- data.1.00
- World's Fair0.99
- TRACK 5·JUNE 30,20260.97
- Security1.00
-
- Image Build + Transparency Pipeline0.98
- AlEngineer0.99
- Two linked stages: trusted base image creation, then transparent runtime bootstrappping.0.99
- World's Fair1.00
- Base image preparation0.98
- [ build time ]0.97
- 2. Manifest + runtime bootstrap0.99
- [ boot time ]0.97
- Base dependencies1.00
- Manifest1.00
- hardened Linux base, kernel/drivers,0.99
- contains workload list, networking rules,1.00
- networking, security agent,1.00
- S3 artifact references, hashes,1.00
- minimal system packages.0.99
- and role settings.0.99
- PCR tooling, verification helpers.0.98
- Measured boot tools1.00
- boot scripts, measured boot utility,1.00
- Transparency commit0.99
- manifest / runtime configuration1.00
- committed to Sigstore.1.00
- Sigstore1.00
- Publish to S31.00
- produces "Base AMI (ZOA)".0.99
- Build pipeline0.97
- submitted to builder,1.00
- Base AMI0.98
- (ZOA)0.97
- 0000.73
- S31.00
- manifest and Sigstore inclusion1.00
- proofs stored in S3.1.00
- S31.00
- VM boot0.98
- Expected measurements1.00
- PCR41.00
- on boot, VM downloads manifest +1.00
- inclusion proofs from S3.1.00
- precompute / record expected1.00
- PCRs for the base image0.97
- (PCR4 / PCR7 / PCR12).0.99
- PCR7 √0.88
- PCR12 √0.91
- Verify + measure0.99
- VM verifies Sigstore inclusion proofs,1.00
- checks runtime measurements, and uses1.00
- base AMI metadata / measurements1.00
- Transparency commit0.99
- committed to Sigstore.1.00
- Sigstore1.00
- Issue certificates0.98
- after verification, create certificates1.00
- manifest to fetch S3 artifacts /1.00
- start containers / configure networking.1.00
- (public)1.00
- aTLS0.97
- used for "aTLS (public)" and1.00
- "mTLS (internal)".1.00
- mTLS1.00
- (internal)1.00
- Output: hardened base AMI + expected PCR set0.98
- Output: bootstrapped workload + verified certificates1.00
- World's Fair0.99
- TRACK 5· JUNE 30, 20260.97
- Security1.00
Transcript
152 cues· 1,804 words· 9,761 chars
- 0:12 Hello, everyone.
- 0:13 I hope this talk will be shorter.
- 0:18 I'm from Amazon.
- 0:20 Our company was acquired about eight months ago, and we built the AI wearable, which is on my hand, which is essentially a microphone that records everything and builds your personal agent, personal AI.
- 0:35 And on top of that, you can extract all the data that you record and plug it to your
- 0:41 systems or agents and do whatever you want.
- 0:47 Just to get in perspective how confidential, how private data we're capturing, a single person usually captures about 10 million tokens per year.
- 1:00 And even within the first week of recording, people usually tell
- 1:08 extremely sensitive stuff to their friends, to their family.
- 1:12 You can learn virtually everything about the person within just like one week of wearing the Bee device, which is extremely sensitive.
- 1:19 I think we're one of the most sensitive capture devices on the market now.
- 1:26 And because of this, we had to encrypt everything, and our mission was to not have access to any of this data
- 1:35 and not being able to look at it, anyone at Amazon.
- 1:39 And it became a little bit challenging for us at Amazon because Amazon itself provides strong security and privacy guarantees.
- 1:48 But if you, Amazon, and you using Amazon stuff, there is much more serious security stuff you need to do.
- 2:00 First of all, we defined a few core principles of what we needed to do for our specific agent.
- 2:06 First of all, we believe the agent should be working all the time, nonstop, for your good.
- 2:13 It should be doing stuff on your behalf.
- 2:16 And we should not consume customer resources, such as batteries and stuff.
- 2:23 So this way, we
- 2:29 This leads us to one specific design of our system.
- 2:36 Current system usually builds on request response system, where you send request to a line from your, say, iPhone, calculate something, and the backend gives you back.
- 2:52 Unfortunately, we already see that this is not enough, that we need to,
- 3:01 that we need to run stuff continuously.
- 3:03 And sometimes for days, we can see this as a glimpse into the future how Cloud Code works.
- 3:11 So just a few months ago, it was more like request response stuff, like change this, change that.
- 3:17 And now it works for hours for us.
- 3:20 We think the same will happen to all your personal agents anyway.
- 3:24 So because of this, we built
- 3:27 a stateful runtime with persistent memory that we still don't have access to.
- 3:33 It can connect to different tools.
- 3:35 It can connect to any third-party services if you program it to.
- 3:41 And we don't require the user device to be online.
- 3:45 So it's fully autonomous.
- 3:47 But at the same time, it's fully controlled by the user.
- 3:53 So encryption system is built on four core ideas that we need to follow.
- 4:01 First of all, the key lives and manage it only on customer device.
- 4:05 So it's user's iPhone or Android device itself.
- 4:08 We don't have the key ourselves.
- 4:11 We don't persist it anywhere.
- 4:13 So a key is stored only on the customer phone.
- 4:20 Everything is encrypted.
- 4:21 We don't have any opt-out.
- 4:23 There's no way to disable it.
- 4:26 There's no way to bypass it.
- 4:28 At the same time, to protect ourselves from internal threats, we do fully transparent audit of all our workloads.
- 4:42 And on top of that, we try to minimize the dependencies
- 4:49 on what we can trust, really.
- 4:53 So any security system, if you do enter an encryption or any kind of encryption, there is a huge problem is key management.
- 5:02 So the first step is like I want to tell you how we manage the key.
loading
Chapters
- 0:00 The most sensitive capture device on the market
- 1:32 The mission: no one, not even Amazon, can read your data
- 2:13 Why the agent runs continuously, not request response
- 3:58 Four principles: the key never leaves your phone
- 4:53 Attestation and a public transparency log
- 6:11 Own inference, confidential compute, and 7 day keys
- 7:14 Signing so no insider can ship unnoticed
- 9:35 Certificates that embed the proofs
- 10:16 Q&A: joining Amazon, 20k lines, and taming agents